CVE-2017-8601 is a critical memory corruption vulnerability in Microsoft Edge's JavaScript engine, affecting Windows 10 and Windows Server 2016. An attacker can exploit this flaw to execute arbitrary code in the context of the current user by crafting malicious web content that improperly handles objects in memory. With a CVSS score of 7.5 (High) and an EPSS score indicating high exploitability, this vulnerability presents a significant risk due to its network-based attack vector and high impact on confidentiality, integrity, and availability. While not listed on the KEV catalog, public exploit code exists (EDB-42479), and the vulnerability has garnered community discussion and media coverage, indicating awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.